2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34691 | MEDIUM | 6.5 | 0.3% | Jun 11, 2024 | Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticate... |
| CVE-2024-34690 | MEDIUM | 5.4 | 0.2% | Jun 11, 2024 | SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t... |
| CVE-2024-34688 | HIGH | 7.5 | 0.5% | Jun 11, 2024 | Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS att... |
| CVE-2024-34686 | MEDIUM | 6.1 | 0.3% | Jun 11, 2024 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which ... |
| CVE-2024-34684 | MEDIUM | 6 | 0.1% | Jun 11, 2024 | On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr... |
| CVE-2024-34683 | MEDIUM | 6.5 | 0.2% | Jun 11, 2024 | An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file,... |
| CVE-2024-33001 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | SAP NetWeaver and ABAP platform allows an attacker to impede performance for legitimate users by crashing or flooding th... |
| CVE-2024-2473 | MEDIUM | 5.3 | 1.2% | Jun 11, 2024 | The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9... |
| CVE-2024-28164 | MEDIUM | 5.3 | 0.3% | Jun 11, 2024 | SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about... |
| CVE-2024-0653 | MEDIUM | 4.8 | 0.2% | Jun 11, 2024 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2024-0627 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The Custom Field Template plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom fiel... |
| CVE-2024-37178 | MEDIUM | 5 | 0.3% | Jun 11, 2024 | SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)... |
| CVE-2024-37177 | HIGH | 8.1 | 0.4% | Jun 11, 2024 | SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are expo... |
| CVE-2024-37130 | HIGH | 7.8 | 0.2% | Jun 11, 2024 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability v... |
| CVE-2024-22261 | MEDIUM | 5.5 | 0.4% | Jun 11, 2024 | SQL-Injection in Harbor allows priviledge users to leak the task IDs |
| CVE-2024-22244 | MEDIUM | 6.1 | 0.4% | Jun 10, 2024 | Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site. |
| CVE-2024-37289 | HIGH | 7.8 | 0.6% | Jun 10, 2024 | An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ... |
| CVE-2024-37169 | MEDIUM | 5.3 | 0.5% | Jun 10, 2024 | @jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if... |
| CVE-2024-37168 | MEDIUM | 5.3 | 0.7% | Jun 10, 2024 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to versions 1.1... |
| CVE-2024-37166 | HIGH | 8.9 | 0.4% | Jun 10, 2024 | ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-control... |
| CVE-2024-36473 | MEDIUM | 5.3 | 0.2% | Jun 10, 2024 | Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack ... |
| CVE-2024-36471 | HIGH | 7.5 | 0.8% | Jun 10, 2024 | Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project adm... |
| CVE-2024-36419 | MEDIUM | 6.1 | 0.2% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prio... |
| CVE-2024-36359 | MEDIUM | 5.4 | 0.4% | Jun 10, 2024 | A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could all... |
| CVE-2024-36358 | HIGH | 7.8 | 0.5% | Jun 10, 2024 | A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now